[PATCH net-next v3] net/ionic: avoid OOB TX partner lookup for hwstamp RXQ

Anand Khoje posted 1 patch 1 month, 2 weeks ago
drivers/net/ethernet/pensando/ionic/ionic_lif.c | 17 +++++++++++++++--
.../net/ethernet/pensando/ionic/ionic_txrx.c    |  7 ++++++-
2 files changed, 21 insertions(+), 3 deletions(-)
[PATCH net-next v3] net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
Posted by Anand Khoje 1 month, 2 weeks ago
The dedicated hardware timestamp RX queue is allocated with q->index
equal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only
contains the regular queue pairs, so using that index to set rxq->partner
can read one entry past txqcqs[] and then write through the derived
pointer.
Only link RX/TX partners for normal queue-pair indexes. Leave the hwstamp
RX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue
has no TX partner.

Fixes: 8eeed8373e1c ("ionic: Add XDP_TX support")
Signed-off-by: Anand Khoje <anand.a.khoje@oracle.com>
Reviewed-by: Si-Wei Liu <si-wei.liu@oracle.com>
Reviewed-by: Shannon Nelson <sln@onemain.com>
Cc: stable@vger.kernel.org
---
v3:
 Use dev_err() and return -ENXIO for a missing normal TX partner.

v2:
 Correct the Fixes tag.

 drivers/net/ethernet/pensando/ionic/ionic_lif.c | 17 +++++++++++++++--
 .../net/ethernet/pensando/ionic/ionic_txrx.c    |  7 ++++++-
 2 files changed, 21 insertions(+), 3 deletions(-)

diff --git a/drivers/net/ethernet/pensando/ionic/ionic_lif.c b/drivers/net/ethernet/pensando/ionic/ionic_lif.c
index fd3ee98..abc8e35 100644
--- a/drivers/net/ethernet/pensando/ionic/ionic_lif.c
+++ b/drivers/net/ethernet/pensando/ionic/ionic_lif.c
@@ -920,8 +920,21 @@ static int ionic_lif_rxq_init(struct ionic_lif *lif, struct ionic_qcq *qcq)
 	};
 	int err;
 
-	q->partner = &lif->txqcqs[q->index]->q;
-	q->partner->partner = q;
+	q->partner = NULL;
+
+	/* Only normal RX queues have matching TX queue partners. */
+	if (q->index < lif->nxqs) {
+		if (!lif->txqcqs ||
+		    q->index >= lif->ionic->ntxqs_per_lif ||
+		    !lif->txqcqs[q->index]) {
+			dev_err(dev, "missing TX queue partner for RX queue %u\n",
+				q->index);
+			return -ENXIO;
+		}
+
+		q->partner = &lif->txqcqs[q->index]->q;
+		q->partner->partner = q;
+	}
 
 	if (!lif->xdp_prog ||
 	    (lif->xdp_prog->aux && lif->xdp_prog->aux->xdp_has_frags))
diff --git a/drivers/net/ethernet/pensando/ionic/ionic_txrx.c b/drivers/net/ethernet/pensando/ionic/ionic_txrx.c
index 301ebee..73998d6 100644
--- a/drivers/net/ethernet/pensando/ionic/ionic_txrx.c
+++ b/drivers/net/ethernet/pensando/ionic/ionic_txrx.c
@@ -545,13 +545,18 @@ static bool ionic_run_xdp(struct ionic_rx_stats *stats,
 		break;
 
 	case XDP_TX:
+		txq = rxq->partner;
+		if (unlikely(!txq)) {
+			err = -EIO;
+			break;
+		}
+
 		xdpf = xdp_convert_buff_to_frame(&xdp_buf);
 		if (!xdpf) {
 			err = -ENOSPC;
 			break;
 		}
 
-		txq = rxq->partner;
 		nq = netdev_get_tx_queue(netdev, txq->index);
 		__netif_tx_lock(nq, smp_processor_id());
 		txq_trans_cond_update(nq);
-- 
2.52.0
Re: [PATCH net-next v3] net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
Posted by Paolo Abeni 1 month, 1 week ago
On 8/13/26 10:37 AM, Anand Khoje wrote:
> The dedicated hardware timestamp RX queue is allocated with q->index
> equal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only
> contains the regular queue pairs, so using that index to set rxq->partner
> can read one entry past txqcqs[] and then write through the derived
> pointer.
> Only link RX/TX partners for normal queue-pair indexes. Leave the hwstamp
> RX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue
> has no TX partner.
> 
> Fixes: 8eeed8373e1c ("ionic: Add XDP_TX support")
> Signed-off-by: Anand Khoje <anand.a.khoje@oracle.com>
> Reviewed-by: Si-Wei Liu <si-wei.liu@oracle.com>
> Reviewed-by: Shannon Nelson <sln@onemain.com>
> Cc: stable@vger.kernel.org
This is net material, you should have set accordingly the target tree
into the subj prefix. Also your SoB should come last.

No need to resend just for this, but keep in mind for future submissions.

/P
Re: [PATCH net-next v3] net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
Posted by Creeley, Brett 1 month, 1 week ago

On 8/13/2026 1:37 AM, Anand Khoje wrote:
> Caution: This message originated from an External Source. Use proper caution when opening attachments, clicking links, or responding.
>
>
> The dedicated hardware timestamp RX queue is allocated with q->index
> equal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only
> contains the regular queue pairs, so using that index to set rxq->partner
> can read one entry past txqcqs[] and then write through the derived
> pointer.
> Only link RX/TX partners for normal queue-pair indexes. Leave the hwstamp
> RX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue
> has no TX partner.
>
> Fixes: 8eeed8373e1c ("ionic: Add XDP_TX support")
> Signed-off-by: Anand Khoje <anand.a.khoje@oracle.com>
> Reviewed-by: Si-Wei Liu <si-wei.liu@oracle.com>
> Reviewed-by: Shannon Nelson <sln@onemain.com>
> Cc: stable@vger.kernel.org
> ---
> v3:
>   Use dev_err() and return -ENXIO for a missing normal TX partner.
>
> v2:
>   Correct the Fixes tag.
>
>   drivers/net/ethernet/pensando/ionic/ionic_lif.c | 17 +++++++++++++++--
>   .../net/ethernet/pensando/ionic/ionic_txrx.c    |  7 ++++++-
>   2 files changed, 21 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/net/ethernet/pensando/ionic/ionic_lif.c b/drivers/net/ethernet/pensando/ionic/ionic_lif.c
> index fd3ee98..abc8e35 100644
> --- a/drivers/net/ethernet/pensando/ionic/ionic_lif.c
> +++ b/drivers/net/ethernet/pensando/ionic/ionic_lif.c
> @@ -920,8 +920,21 @@ static int ionic_lif_rxq_init(struct ionic_lif *lif, struct ionic_qcq *qcq)
>          };
>          int err;
>
> -       q->partner = &lif->txqcqs[q->index]->q;
> -       q->partner->partner = q;
> +       q->partner = NULL;
> +
> +       /* Only normal RX queues have matching TX queue partners. */
> +       if (q->index < lif->nxqs) {
> +               if (!lif->txqcqs ||
> +                   q->index >= lif->ionic->ntxqs_per_lif ||
> +                   !lif->txqcqs[q->index]) {
> +                       dev_err(dev, "missing TX queue partner for RX queue %u\n",
> +                               q->index);
> +                       return -ENXIO;
> +               }
> +
> +               q->partner = &lif->txqcqs[q->index]->q;
> +               q->partner->partner = q;
> +       }
>
>          if (!lif->xdp_prog ||
>              (lif->xdp_prog->aux && lif->xdp_prog->aux->xdp_has_frags))
> diff --git a/drivers/net/ethernet/pensando/ionic/ionic_txrx.c b/drivers/net/ethernet/pensando/ionic/ionic_txrx.c
> index 301ebee..73998d6 100644
> --- a/drivers/net/ethernet/pensando/ionic/ionic_txrx.c
> +++ b/drivers/net/ethernet/pensando/ionic/ionic_txrx.c
> @@ -545,13 +545,18 @@ static bool ionic_run_xdp(struct ionic_rx_stats *stats,
>                  break;
>
>          case XDP_TX:
> +               txq = rxq->partner;
> +               if (unlikely(!txq)) {
> +                       err = -EIO;
> +                       break;
> +               }
> +
>                  xdpf = xdp_convert_buff_to_frame(&xdp_buf);
>                  if (!xdpf) {
>                          err = -ENOSPC;
>                          break;
>                  }
>
> -               txq = rxq->partner;
>                  nq = netdev_get_tx_queue(netdev, txq->index);
>                  __netif_tx_lock(nq, smp_processor_id());
>                  txq_trans_cond_update(nq);

LGTM. Thanks for the fix.

Reviewed-by: Brett Creeley <brett.creeley@amd.com>
> --
> 2.52.0
Re: [PATCH net-next v3] net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
Posted by Simon Horman 1 month, 2 weeks ago
On Thu, Aug 13, 2026 at 08:37:05AM +0000, Anand Khoje wrote:
> The dedicated hardware timestamp RX queue is allocated with q->index
> equal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only
> contains the regular queue pairs, so using that index to set rxq->partner
> can read one entry past txqcqs[] and then write through the derived
> pointer.
> Only link RX/TX partners for normal queue-pair indexes. Leave the hwstamp
> RX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue
> has no TX partner.
> 
> Fixes: 8eeed8373e1c ("ionic: Add XDP_TX support")
> Signed-off-by: Anand Khoje <anand.a.khoje@oracle.com>
> Reviewed-by: Si-Wei Liu <si-wei.liu@oracle.com>
> Reviewed-by: Shannon Nelson <sln@onemain.com>
> Cc: stable@vger.kernel.org
> ---
> v3:
>  Use dev_err() and return -ENXIO for a missing normal TX partner.
> 
> v2:
>  Correct the Fixes tag.

Reviewed-by: Simon Horman <horms@kernel.org>